Recorded evidence

See what actually ran.

One synthetic application. Real GitHub Actions executions. Inspect the observations, tested commits and reasons behind three different results.

Recorded under the earlier SpecProof name on 30 September 2026. This is an internal acceptance rehearsal, not customer usage or proof that every profile works.

Bracel / Recorded GitHub resultscustomer-ci

Recorded 30 September 2026 · 0.1.0-beta.4

FAIL

At least one protection observed behaviour that violates its approved rule.

6 executed behaviors

Approved rules and expected behavior

server.js changed and matched the protected paths. Rules were read from the base commit.

refund-cap · FAIL

After refunding 5000 of a captured 10000, reject a second refund of 5001 with a client error and keep the refunded total at 5000.

refund.amount-cap v1 · revision 303b54929ac2bb99

admin-auth · PASS

Deny GET /admin/refunds without credentials; never return a success status.

http.auth-required v1 · revision 1bfdc3a3a658c10e

  1. POST /payments created a synthetic payment: observed HTTP 201.
  2. GET /payments/{paymentId} read the refunded total: 0.
  3. POST /payments/{paymentId}/refunds with a valid partial amount 5000 of 10000: observed HTTP 201.
  4. GET /payments/{paymentId} read the refunded total: 5000.
  5. POST /payments/{paymentId}/refunds with 5001, which exceeds the remaining 5000: observed HTTP 201.
  6. GET /admin/refunds without credentials: observed HTTP 401; denied, as required.

The walkthrough

Change the code. Run the rule. Read the result.

A local recording: remove the refund limit, execute real HTTP requests with the release-owned verifier, observe FAIL, restore the limit and rerun to PASS. The code edit is scripted; this is not a GitHub run or an automated Fix job.

Synthetic payment fixture · values shown in minor currency units. Download this recording’s execution observations →

Verify the provenance

Evidence with a boundary.

All three runs used release 0.1.0-beta.4. Runtime tree digest:

f6de3b78cac43873e872e23b246a6854ea8db589a03743b37adead6ce8e141ec

Rules came from the base commit. The tested commit matched the PR head. Digests detect accidental corruption; they are not signatures or independent attestation.

Download curated observations ↓

What this establishes

The seeded refund violation was reported as FAIL. The valid refactor was reported as PASS for the executed scenarios. The unsupported profile executed nothing and reported UNKNOWN.

What it does not establish

No Fix job is shown. No customer deployment, universal correctness, production error rate, database profile acceptance or competitor superiority is claimed. The runner and workflow remain under the repository owner's control.

Source repositories are private: source links require authorized GitHub access. This public-ready extract includes only synthetic observations, release identifiers and hashes; no raw job logs, source code, credentials or customer data.

Read the acceptance boundaries →

Make your first rule inspectable.